Input validation vulnerability in WordPress 6.8.2

A recently disclosed vulnerability in WordPress has come to light after being unintentionally revealed by a third party. The issue could allow users with Author-level or higher permissions to access certain sensitive information, but it cannot be exploited by visitors without elevated privileges. At the moment there is no confirmed patch available, though some security researchers (like patchstack) report that the WordPress team is investigating the matter. Because the vulnerability requires already-privileged access, the overall risk to most WordPress websites is considered low.

We recommend to keep an eye out for WordPress core updates, as we expect this vulnerability to be patched within a few days.

Detected in:

WordPress Open vulnerable versions: * <= 6.8.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.